Who really runs a Luxembourg fund?

As funds become more specialised, outsourced and automated, the distance between who performs the work and who remains accountable is becoming harder to ignore.

In a market of high complexity, high stakes, high volume and size of transactions, with so many specialised servicing parties (AIFM, depositaries, fund administrators, auditors, legal advisors, etc. ), as well as delegated functions, the board members still remain at the centre of governance and accountability.

That division of labour is one of Luxembourg’s strengths. It also creates a deceptively simple governance question: when so much of the work is performed elsewhere, who really runs the fund?

The answer matters because operational delegation does not necessarily carry the board’s own responsibilities with it. The CSSF’s 2025 Annual Report records administrative sanctions imposed directly on natural-person directors in the fund sector, while Luxembourg tax law provides, in defined circumstances, mechanisms capable of reaching persons involved in the management of a company personally.

The person performing a function and the person accountable for overseeing it are not necessarily the same person.

Understanding that distinction requires looking first at the architecture Luxembourg has built around investor trust.

The Arhitecture of Trust

Just like any transaction around the world depends on the trust between parties, investment fund market is build on the same simple foundation: TRUST - investors entrust their capital to other people. Given the scale, complexity, cross border nature as well as impact not only on the investors but also the overall financial stability, the civil and commercial laws become insufficient for the scope of protection. This explains the existent multi-layered regulatory framework as well as the existence of the supervision bodies in the field of investment funds.

At European level, investment funds and their managers are governed mainly through legal frameworks such as UCITS and AIFMD, complemented by other directly applicable EU regulations.

On the oversight side, there are:

  • the European Securities and Markets Authority (ESMA) promotes supervisory convergence across national authorities

  • the European Central Bank (ECB)

  • the European Systemic Risk Board (ESRB) contributing to monetary and systemic risk oversight.

At Luxembourg level, this European legal framework is implemented and supplemented through laws such as:

  • the Law of 17 December 2010 on undertakings for collective investment,

  • the Law of 12 July 2013 on alternative investment fund managers,

  • the SIF Law of 13 February 2007,

  • the SICAR Law of 15 June 2004 and

  • the RAIF Law of 23 July 2016, together with regulations and circulars from CSSF.

On the institutional side, CSSF is the supervisor of the financial sector which aims to protect the investors and the stability of the financial system. Banque Centrale de Luxembourg (BCL) performs important statistical, liquidity and financial stability functions as well as working together with CSSF on fund data used for statistical and prudential purposes. Financial Intelligence Unit (FIU) is another institution part of this framework, focused on money laundering and terrorist financing.

This architecture exists to create trust for investors, TRUST that the the right rules are applied to the investment fund ecosystem and TRUST that the institutions in charge of supervision ensure that the rules are respected.

For Luxembourg, this trust becomes an economic asset and it is essential as its success depends heavily on the confidence in its legal framework, specialised financial ecosystem and CSSF supervision.

However, all these regulations and market practice have created a highly specialised market and participants: AIFMs/ManCos, investment managers, administrators, depositaries, auditors, risk and compliance functions, each with distinct responsibilities and in many cases, regulatory oversight. This specialisation creates expertise and checks and balances, but also fragmentation and coordination risk.

What is the connection with the board members?

Companies act through people. The board members are the ones appointed and legally responsible for the management of the funds and the other entities in the fund structure. They are also the ones to appoint the servicing parties and sign the contractual framework for AIFMs/ManCos, investment managers, administrators, depositaries, auditors, legal advisors, etc..

The terminology may be confusing because company law, CSSF and the fund market professionals use different but overlapping vocabularies.

From a Luxembourg company law perspective, the starting point is the type of a legal entity. A member of the board of directors of an SA, is an administrateur (director), while other legal entities forms may be managed by one or more gérants (managers). In regulatory language, the CSSF has more neutral references: management body or governing body and members of the management body/governing body. For example, Circular 18/698 expressly refers to the mandates and professional activities of members of an IFM’S management body/governing body and requires them to be reported to the CSSF.

The fund market professionals add another classification. The Luxembourg Institute of Governance (ILA) distinguishes between Executive Directors, Non-Executive Directors (NEDs) and Independent Non-Executive Directors (iNEDs). ILA defines NED as a board member external to executive management, the company group or the entities servicing the company, while an iNED is a subset of NEDs who in addition, are free from material relationships, influences or circumstances capable of compromising their independent judgement.

Fund administrators usually provide such board mandates as a service by appointing one of their employees on the board of the client entity and refer to such mandate as Directorship mandate.

The Duality of Legal Personality

Since companies act through people, it’s important to make this distinction between companies (legal persons) and people (natural persons). A company is a legal person, separate from its shareholders, directors and managers. It can own assets, engage the company toward third parties, incur liabilities and sue or be sued in its own name. But legal personality is a juridical construct: a company cannot itself think, deliberate, challenge information, exercise judgement or physically sign a document. It must ultimately act through natural persons. (And before someone asks about AI agents: they do not have separate legal personality. However autonomous the technology may appear, the law still looks for the natural or legal persons behind its development, deployment and use when assessing liability.)

This separation between the legal personalities has important consequences:

  1. Separation of patrimony. The company’s assets and liabilities belong to the company. Directors may exercise significant powers over those assets but they do not own them. Control does not amount to ownership. However, in practice, there are exceptions that apply in tax matters as well as fines imposed by regulator.

  2. Separate rights and obligations. The company enters into contracts and assumes obligations in its own name. A director who signs an agreement on behalf of the company does not, merely by acting in that capacity, become personally party to the company’s obligations. Similarly, the company can sue and be sued in its own name.

  3. Acting through corporate organs and representatives. Although the company has its own legal personality, it cannot physically act or exercise judgement by itself. It acts through its competent corporate organs and authorised representatives. A natural person may therefore negotiate, approve or sign a transaction while the resulting rights and obligations are attributed to the company. The individual performs the act, the company may bear its legal effects.

  4. Delegation of powers. The fact that a board has management powers does not mean that every function must be performed personally by its members. Certain powers or functions may be delegated where permitted by law, the articles of association and the applicable regulatory framework. For an SA, for example, the board may delegate day-to-day management and the related representation to one or more directors, managers or other agents. However, delegation has limits: general management cannot simply be transferred away from the board. Delegation therefore changes who performs or exercises a particular function. It does not, by itself, eliminate the responsibilities that the law continues to place on the board.

  5. Continuity. The company’s existence is independent from the individuals managing it. Directors may be appointed, replaced, resign or be removed without changing the identity of the legal person. The company survives the individuals through whom it acts.

Legal personality separates the company from its directors. The corporate mandate (mandate sociale) is what connects them.

Personal liability

In the 2025 Annual Report of Commission de Surveillance du Secteur Financier (CSSF) reported administrative fines imposed directly on directors - natural persons, for failures related to filling of annual accounts.

For tax matters, the separation of patrimony between companies and their directors is blurred. Luxembourg has legal provisions that allow for appel en garantie for managers against certain de jure or de facto managers involved in the day-to-day management of a taxable person, potentially making them personally and jointly liable for unpaid taxes. In QJ v AEDT and État du Grand-duché de Luxembourg, C-158/25, judgment of 16 July 2026, the CJEU examined this mechanism in the context of VAT. The Court confirmed that the appel en garantie provided for under Articles 67-1 to 67-3 LTVA enables the Luxembourg tax administration to recover VAT owed by a company from qualifying persons involved in its day-to-day management where the statutory conditions for personal liability are met.

What Does a Diligent Director Actually Look Like?

The standard of diligence for a board member is rooted in the civil-law concept of the bonus pater familias: the prudent and diligent person placed in comparable circumstances.

The civil-law duty of diligence provides the general standard, while the regulatory framework from CSSF and the professional recommendations from ILA make that standard increasingly concrete and observable.

The CSSF does not merely expect a director to be “diligent” in the abstract. In the IFM context, Circular 18/698 translates that expectation into measurable constraints. Members must devote sufficient time and attention to their functions, professional engagements are subject to a 1,920-hour annual threshold and no more than 20 mandates in regulated entities and operating companies. Where thresholds are exceeded, the candidate must explain how sufficient time and attention will nevertheless be ensured, taking account of the number, size, nature, scale and complexity of the entities concerned.

Likewise, the broader CSSF governance approach translates suitability into identifiable characteristics: directors are expected to possess sufficient knowledge, skills and experience, be of good repute and devote sufficient time to their responsibilities. ILA adds a best-practice articulation of what diligence looks like at the level of the individual director: obtaining sufficient information before acting, exercising independent judgment, seeking additional information or professional advice where appropriate and ensuring that material disagreement is properly reflected in the minutes.

Beyond suitability, there is also the question of effectiveness. Having the qualifications and time to sit on a board is not the same as performing the mandate effectively. ILA’s guidance on board effectiveness therefore looks beyond formal compliance to how the board actually functions, including its composition, skills, processes, dynamics and the contribution of individual directors. It recommends periodic evaluation of whether the board functions effectively and whether individual directors continue to contribute effectively and demonstrate sufficient commitment.

Taken together, these standards progressively narrow the practical meaning of the duty of diligence. The question is no longer simply whether a director was formally appointed and attended meetings, but whether that director was suitable for the mandate, had sufficient capacity and time to perform it, was adequately informed, exercised independent judgment and challenge, and contributed effectively to the board’s decision-making and oversight. In this sense, the traditional duty of diligence is increasingly translated into observable standards of board conduct and effectiveness.

If It Isn’t Documented, Did It Happen?

For directors, diligence is better treated as a governance strategy than a retrospective defence. A board should know which risks can create operational, regulatory, tax or potentially personal exposure and build those risks into its meeting agendas.

Quarterly meetings provide a natural checkpoint. Agendas can be structured around both operational priorities and governance risk: operational status, regulatory obligations, tax and statutory filings, compliance matters, delegated activities and unresolved actions. Material obligations should be tabled, ownership identified, completion verified and exceptions explained. The point is not for directors to perform work delegated to specialists. It is to ensure that critical obligations do not disappear into the delegation chain and that oversight is properly exercised.

That makes the company secretary and the infrastructure surrounding the board more than an administrative function. Board calendars, dashboards, filing schedules, action logs and oversight trackers turn governance obligations into visible checkpoints and create a record of what the board knew, challenged and followed up.

That is also the rationale behind Diderich Consulting’s Board Calendar™, Board Dashboard™, Board Meeting Toolkit™ and Board Oversight Tracker: creating a governance system that helps directors identify what matters, put it before the board and the responsible parties at the right time, track it to completion and document the oversight exercised.

Good governance leaves a trail. When liability is at stake, that trail matters.

When the Regulator Has AI Agents, Can Boards Stay Analogue?

The CSSF’s 2025 Annual Report opens not with a regulation, but with HAL 9000. Claude Marx invokes 2001: A Space Odyssey to frame the emerging problem of autonomous systems: machines capable of reasoning, acting and pursuing objectives with diminishing human intervention. The regulatory message follows quickly. Boards and executive teams, the CSSF says, need to understand frontier-AI risks, set strategic direction and oversee how control functions manage them.

The challenge is also one of speed. The CSSF describes financial institutions as operating on planning cycles measured in years while AI technology can change almost overnight. Luxembourg finance, meanwhile, has already adopted generative AI across front, middle and back office functions.

The regulator is responding with technology of its own. SKAI, the CSSF’s new AI-agent platform, combines public and sovereign AI models with configurable agents capable of analysing information, interacting with knowledge bases and supporting business processes. The CSSF is already using conversational AI for document summarisation, data searches and drafting assistance, while AI models are also being deployed for cybersecurity anomaly detection.

However, for fund board members, AI is only half the challenge. The industry is becoming both more automated and more dependent on third parties. The CSSF's 2025 Annual Report warns of concentration among technology and AI providers, vendor lock-in and growing third-party dependencies, while its supervisory work shows that ICT third-party providers are already a significant issue for management companies. This comes on top of a fund model already built around delegation to investment managers, administrators and other specialist providers, who further outsource outside Europe. For directors, the result is a broader and faster-moving oversight perimeter: they need to understand what has been delegated, what technology sits behind it, where further outsourcing occurs and whether the controls and information reaching the board remain adequate. AI may make the operating chain faster and outsourcing may make it more complex, but neither makes the board's own duties disappear.

That also calls for a change in board strategy. Directors cannot realistically oversee an AI-enabled industry with an entirely analogue governance model. The volume of information is increasing, processes are accelerating and the number of technology and third-party dependencies requiring oversight is growing. The CSSF itself has responded by introducing SKAI, its AI-agent platform, using AI for document summarisation, data searches, drafting and, progressively, more advanced agent-based assistance. The lesson for boards is not that judgment should be automated but that the work supporting that judgment should increasingly be augmented by technology. Secure AI tools can help directors navigate board packs, identify exceptions, monitor regulatory and filing deadlines, track delegated activities and follow outstanding actions. The objective should be simple: use AI to create more time for the work that cannot be automated: challenge, judgment and decision-making.

So, Who Really Runs a Luxembourg Fund?

A Luxembourg fund is not run by one person or institution. It operates through a network of boards, AIFMs and management companies, investment managers, administrators, depositaries, control functions, advisers and technology providers. Each performs a different role, carries its own responsibilities and contributes to the functioning of the fund.

But operational responsibility and board accountability are not the same thing. Functions can be delegated, services outsourced and processes automated without necessarily removing the duties that remain attached to the board’s own mandate. The board is not expected to replicate the work of specialists. It is expected to understand the structure it governs, remain sufficiently informed, exercise independent judgment and challenge, and oversee the matters for which it remains responsible.

That distinction becomes more important as the operating model grows more complex. The further execution moves from the boardroom, the more important visibility and effective oversight become. Accountability ultimately requires directors to be able to understand what was delegated, how it was overseen, what information reached the board and what the board did with it.

So, who really runs a Luxembourg fund? Many parties run its operations. The board remains at the centre of its governance and accountable for the proper exercise of its own mandate.

The technology changes. The providers change. The board’s accountability remains.

Previous
Previous

Luxembourg Has €8.3 Trillion in Fund Assets. How Much Actually Stays Here?